Question 26

Please read this scenario prior to answering the question
Your role is that of a senior architect, reporting to the Chief Enterprise Architect, at a medium-sized company with 400 employees. The nature of the business is such that the data and the information stored on the company systems is their major asset and is highly confidential.
The company employees travel extensively for work and must communicate over public infrastructure using message encryption, VPNs, and other standard safeguards. The company has invested in cybersecurity awareness training for all its staff. However, it is recognized that even with good education as well as system security, there is a dependency on third-parly suppliers of infrastructure and software.
The company uses the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The CTO is the sponsor of the activity.
The Chief Security Officer (CSO) has noted an increase in ransomware (malicious software used in ransom demands) attacks on companies with a similar profile. The CSO recognizes that no matter how much is spent on education, and support, it is likely just a matter of time before the company suffers a significant attack that could completely lock them out of their information assets.
A risk assessment has been done and the company has sought cyber insurance that includes ransomware coverage. The quotation for this insurance is hugely expensive. The CTO has recently read a survey that stated that one in four organizations paying ransoms were still unable to recover their data, while nearly as many were able to recover the data without paying a ransom. The CTO has concluded that taking out cyber insurance in case they need to pay a ransom is not an option.
Refer to the scenario
You have been asked to describe the steps you would take to improve the resilience of the current architecture?
Based on the TOGAF standard which of the following is the best answer?
  • Question 27

    Please read this scenario prior to answering the question
    You are employed as an Enterprise Architect at a technology company, reporting directly to the Chief Enterprise Architect. The company supplies personnel and delivers cloud- based solutions to numerous government agencies.
    The nature of the business is such that the data and the information stored on the company systems is the company's major asset and is highly confidential. The company employees work remotely and need constant access to the company systems, which is done by the public infrastructure. They use message encryption, secure internet connections using Virtual Private Networks (VPNs), and other standard security measures. The company provides computer security awareness training for all its staff.
    The Chief Security Officer (CSO) has noted an increase in distributed denial of service (DDoS) attacks on companies with a similar profile. The CSO understands that even with thorough preparation, a major attack could stop employees from being able to do their jobs. This could lead to a large financial loss, damage to the company's reputation with customers, and employees being unable to work.
    A risk assessment has been completed and the company has looked for cyber insurance that covers such attacks. The price for this insurance is very high. The CTO has decided not to get cyber insurance to cover such attacks.
    The company follows the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor of the activity. The practice uses an iterative approach for its architecture development.
    This has enabled the decision makers to gain valuable insights into the different aspects of the business Please read this scenario prior to answering the question You have been asked to describe the steps you would take to strengthen the current architecture to improve data protection.
    Based on the TOGAF standard which of the following is the best answer?
  • Question 28

    Please read this scenario prior to answering the question
    You are employed as an Enterprise Architect in a team at a large company. The company sells luxury food and drinks in more than 10,000 stores worldwide. The company is a leader in using technology to connect with its customers. This includes online ordering, mobile apps, and rewards programs. The company is also famous for bringing new ideas to the market, like ordering through apps, using Al to suggest personalized options, self-service pickup stations, and changing prices based on demand.
    The stores are open every day. They send timely sales data to a central system that manages inventory. This system can predict what products are needed, adjust how much stock there is, and order more stock automatically. The stores and the main inventory system work directly with the mobile apps, allowing orders to be made online. The central inventory system is located at the company's main data center.
    The company will merge with a major competitor. This competitor has a synergistic business. Leaders from both companies have told shareholders that the merger will happen fast. There will be minimal impact for customers. All stores will keep the current brand names. They will combine their systems, choosing the best ones to use.
    This means their store management and back-office systems will become one. They will stop using duplicate systems and use one main system to manage the stores.
    They will also cut down on the number of back-office applications they use.
    The Request for Architecture Work to oversee the merger has been approved.
    Stakeholders, concerns, and business requirements have been identified. The stakeholders have made it clear that they expect to continue to be able to innovate quickly, and that changes should not restrict that capability. The scope of what is inside and what is outside the architecture efforts has been confirmed. The next step is to revisit and review the Architecture Principles, as they form part of the constraints on architecture work.
    Business Continuity is essential given that the business depends on real-time ordering and automated inventory management. During the systems integration, maintaining service for customers and inventory operations must be prioritized Refer to the scenario You have been asked to identify the most relevant Architecture Principles for the merger besides Business Continuity.
    Based on the TOGAF standard, which of the following is the best answer?
    [Note: You should assume that the company follows the example set of Architecture Principles provided in the TOGAF standard, ADM Techniques, Architecture Principles chapter.]
  • Question 29

    Please read this scenario prior to answering the question
    You are employed as an Enterprise Architect working within the Enterprise Architecture (EA) team at an electric vehicle manufacturer. The company focuses on designing, manufacturing, and advancing battery technology for sustainable transportation, while also investing in charging infrastructure, autonomous driving systems, and renewable energy integration.
    The company is introducing a major change to its vehicle design over a five-year period. This will be a cross-functional effort between hardware and software teams, delivering significant new features in the vehicles they manufacture. It is planned to be developed in phases. An architecture to support strategy has been completed with a roadmap for a set of projects.
    The EA team has taken over the architecture for the hardware and software automotive platform used by current vehicles, some of which will be used again in the new vehicle design. The EA team has started to pick which parts of the architecture to use again.
    The presentation and access to different variations of data that the company plans to offer through its vehicles creates a design challenge. The application portfolio and supporting infrastructure must connect with multiple cloud services and data repositories in different countries to be able to handle the data at a large scale.
    Enough of the Business Architecture has been defined, so that work can commence on the Information Systems and Technology Architectures. Those architectures need to be defined to support the primary business services that the company plans to provide. These services will handle and use the data created by vehicles, preparing the way for self-driving vehicles in the future.
    The company uses the TOGAF standard as the basis for its Enterprise Architecture framework. The EA team reports to the Chief Technical Officer (CTO), who is the sponsor of the EA program. The CTO requires that the EA team follow the purpose- based EA Capability model as described in the TOGAF Series Guide: A Practitioners' Approach to Developing Enterprise Architecture Following the TOGAF® ADM.
    Refer to the scenario
    How would you plan, organize, and manage the architecture development at this stage?
    Based on the TOGAF standard which of the following is the best answer?
  • Question 30

    You are working as an Enterprise Architect within an Enterprise Architecture (EA) team at a multinational energy company. The company is committed to becoming a net-zero emissions energy business by 2050. To achieve this, the company is focusing on shifting to renewable energy production and adopting eco-friendly practices.
    The EA team, which reports to the Chief Technical Officer (CTO), has been tasked with overseeing the transformation to make the company more effective through acquisitions. The company plans to fully integrate these acquisitions, including merging operations and systems.
    To address the integration challenges, the EA team leader wants to know how to manage risks and ensure that the company succeeds with the proposed changes. Based on the TOGAF Standard, which of the following is the best answer?